A Model-driven Approach for Securing Software Architectures

被引:0
|
作者
Neri, Mario Arrigoni [1 ]
Guarnieri, Marco [2 ]
Magri, Eros [3 ]
Mutti, Simone [1 ]
Paraboschi, Stefano [1 ]
机构
[1] Univ Bergamo, Dip Ingn Informat & Metodi Matemat, Bergamo, Italy
[2] Swiss Fed Inst Technol, Inst Informat Secur, Zurich, Switzerland
[3] Comelit Grp SpA, Comelit R&D, Rovetta S Lorenzo, Italy
关键词
Access Control; Model-driven Security; Security Policy; Software Architectures;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Current IT systems consist usually of several components and services that communicate and exchange data over the Internet. They have security requirements that aim at avoiding information disclosure and at showing compliance with government regulations. In order to effectively handle the security management of complex IT systems, techniques are needed to help the security administrator in the design and configuration of the security architecture. We propose a model-driven security approach for the design and generation of concrete security configurations for software architectures. In our approach the system architect models the architecture of the system by means of UML class diagrams, and then the security administrator adds security requirements to the model by means of Security4UML, a UML profile. From the model enriched with security requirements, the concrete security configuration is derived in a semi-automated way. We present a tool that supports this model-driven approach, and a case study that involves a distributed multi-user meeting scheduler application.
引用
收藏
页码:595 / 602
页数:8
相关论文
共 50 条
  • [21] Model-driven Development of Safety Architectures
    Denney, Ewen
    Pai, Ganesh
    Whiteside, Iain
    [J]. 2017 ACM/IEEE 20TH INTERNATIONAL CONFERENCE ON MODEL DRIVEN ENGINEERING LANGUAGES AND SYSTEMS (MODELS 2017), 2017, : 156 - 166
  • [22] Model-driven software verification
    Holzmann, GJ
    Joshi, R
    [J]. MODEL CHECKING SOFTWARE, 2004, 2989 : 76 - 91
  • [23] Model-driven software adaptation
    Bencomo, Nelly
    Blair, Gordon
    France, Robert
    [J]. OBJECT-ORIENTED TECHNOLOGY: ECOOP 2007 WORKSHOP READER, 2008, 4906 : 132 - +
  • [24] A model-driven approach to enable the simulation of complex systems on distributed architectures
    Bocciarelli, Paolo
    D'Ambrogio, Andrea
    Falcone, Alberto
    Garro, Alfredo
    Giglio, Andrea
    [J]. SIMULATION-TRANSACTIONS OF THE SOCIETY FOR MODELING AND SIMULATION INTERNATIONAL, 2019, 95 (12): : 1185 - 1211
  • [25] A Model-Driven Approach for Solving the Software Component Allocation Problem
    Al-Azzoni, Issam
    Blank, Julian
    Petrovic, Nenad
    [J]. ALGORITHMS, 2021, 14 (12)
  • [26] A MODEL-DRIVEN APPROACH TO MANAGING AND CUSTOMIZING SOFTWARE PROCESS VARIABILITIES
    Aleixo, Fellipe Araujo
    Freire, Marilia Aranha
    dos Santos, Wanderson Camara
    Kulesza, Uira
    [J]. ICEIS 2010: PROCEEDINGS OF THE 12TH INTERNATIONAL CONFERENCE ON ENTERPRISE INFORMATION SYSTEMS, VOL 3: INFORMATION SYSTEMS ANALYSIS AND SPECIFICATION, 2010, : 92 - 100
  • [27] A Model-Driven Approach for the Design and Implementation of Software Development Methods
    Cervera, Mario
    Albert, Manoli
    Torres, Victoria
    Pelechano, Vicente
    [J]. INTERNATIONAL JOURNAL OF INFORMATION SYSTEM MODELING AND DESIGN, 2012, 3 (04) : 86 - 103
  • [28] A Model-Driven Architecture Approach to Accelerate Software Code Generation
    Bhadra, Mayuri
    Lopera, Daniela Sanchez
    Kunzelmann, Robert
    Ecker, Wolfgang
    [J]. 2024 7TH INTERNATIONAL CONFERENCE ON SOFTWARE AND SYSTEM ENGINEERING, ICOSSE 2024, 2024, : 23 - 30
  • [29] A model-driven approach for engineering trust and reputation into software services
    Moyano, Francisco
    Fernandez-Gago, Carmen
    Lopez, Javier
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2016, 69 : 134 - 151
  • [30] An innovative model-driven slicing approach for testing adaptive software
    [J]. Babamir, Seyed Morteza (babamir@kahanu.ac.ir), 1600, Bentham Science Publishers (10):